Windows Server Update Hardening for Jan.13 Update
Microsoft is hardening a Windows Server component.
The focus is on Windows Deployment Services (WDS), which supports “hands-free deployment” using an Unattend.xml (Answer file) for automated installations. A vulnerability (CVE-2026-0386) was discovered that could allow attackers to intercept this file over insecure channels, leading to remote code execution (RCE) and credential theft.
Key Points:
- Patch Tuesday Update (KB5074109) introduced the first phase of changes on January 13, 2026.
- Microsoft will phase out hands-free deployment over insecure connections:
- Currently still supported but discouraged.
- IT admins can disable it via registry keys now.
- By April 2026, hands-free deployment will be blocked by default unless explicitly re-enabled.
- Microsoft warns that re-enabling this feature after April will be considered insecure.
- Additional event logs are being added to help admins monitor deployment configurations.
- Despite the active vulnerability, Microsoft is not immediately disabling insecure configurations but may do so later.
- IT admins should review guidance and prepare alternatives for deployment methods.
.png)